WordPress Plugin Vulnerabilities

MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion

Description

The plugins do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.

Proof of Concept

Affects Plugins

Fixed in 1.7.8.5

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Enrico Marcolini - Claudio Marchesini - Dottor Marc
Submitter
Enrico Marcolini - Claudio Marchesini - Dottor Marc
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-11 (about 2 days ago)
Added
2026-09-11 (about 2 days ago)
Last Updated
2026-09-11 (about 1 day ago)

Other